Privacy policy

 

Last updated: 3 March 2026

ELFRIEDE/KASTULUS operates this shop and this website, including all associated information, content, features, tools, products and services, to provide you, the customer, with a personalised shopping experience (the “Services”). ELFRIEDE/KASTULUS is powered by Shopify, which enables us to provide you with the Services. This Privacy Policy describes how we collect, use or disclose personal data when you visit or use the website, make a purchase or other transaction using the Services, or otherwise communicate with us. If there is a conflict between our Terms and Conditions and this Privacy Policy, this Privacy Policy shall prevail with regard to the collection, processing and disclosure of your personal data.

 

Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you have read this Privacy Policy and agree to the collection, use and disclosure of your data as described in this Privacy Policy.

 

What personal data do we collect or process?

When we use the term ‘personal data’, we are referring to information that identifies you or another person, or that can be directly linked to you. Personal data does not include information that has been collected anonymously or anonymised in such a way that it is no longer possible to identify you or link it to you. Depending on how you interact with the Services, where you live and as permitted or required by applicable law, we may collect or process the following categories of personal data, including inferences drawn from such personal data:

  • Contact details, including name, postal address, billing address, delivery address, telephone number and email address.

  • Financial data, including credit and debit card numbers, financial account numbers, payment card details, financial account information, transaction details, payment method, payment confirmation and other payment details.

  • Account information, including your username, password, security questions, configurations and settings.

    Transaction information, including the items you view, add to your basket, add to your wishlist or purchase, return, exchange or cancel, as well as your past transactions.

  • Communication with us, including the information you provide when communicating with us, for example when you submit a query to customer support.

  • Device information, including information about your device, browser or network connection, IP address and other unique identifiers

  • Usage information, including information about your interaction with the Services, including how and when you interact with or browse the Services.

 

Sources of personal data

We may collect personal data from the following sources:

  • Directly from you We collect data, for example, when you create an account, access or use the services, communicate with us, or otherwise provide us with your personal data.

  • Automatically via our services We collect data from your device, when you use our products or services or visit our website, and through the use of cookies and similar technologies

  • From our service providers We collect data, for example, when we instruct service providers to implement certain technologies, and when they collect or process your personal data on our behalf.

  • From our partners and other third-party providers

 

How do we use your personal data?

Depending on how you interact with us or which of our services you use, we may use personal data for the following purposes:

  • Provision, customisation and improvement of the Services. We use your personal data to provide you with the Services. This includes, amongst other things, fulfilling our contract with you, processing your payments, fulfilling your orders, storing your configurations and the items you are interested in, sending notifications relating to your account, creating, maintaining and otherwise managing your account, organising delivery, facilitating returns and exchanges, enabling you to leave reviews, and creating a personalised shopping experience for you, for example by recommending products based on your purchases. This may also include using your personal data to better tailor and improve the Services.

  • Marketing and advertising. We use your personal data for marketing and advertising purposes, for example to send you marketing and promotional communications by email, text message or post, and to display online advertisements for products or services relating to the Services or other websites, including based on items you have previously purchased or added to your basket, as well as other activities relating to the Services.

  • Security and fraud prevention. We use your personal data to authenticate your account, provide a secure payment and shopping experience, detect, investigate or take action against potential fraudulent, illegal, unsafe or malicious activities, protect public safety, and ensure the security of our services. If you decide to use the Services and register an account, you are responsible for protecting your account login details. We strongly recommend that you do not share your username, password or other login details with anyone else.

  • Communication with you. We use your personal data to provide you with customer support and effective services, to respond promptly to your enquiries, and to maintain our business relationship with you.

  • Legal reasons. We use your personal data to comply with applicable law or to respond to lawful legal processes, including requests from law enforcement or regulatory authorities; to investigate or participate in civil investigations, potential or actual legal disputes, or other adversarial proceedings; and to investigate potential breaches of our terms and policies or to enforce those terms and policies.

 

How do we share personal data?

In certain circumstances, we may share your personal data with third parties for legitimate purposes in accordance with this privacy policy. Such circumstances may include the following:

  • In the case of Shopify, these are service providers and other third parties who provide services on our behalf (e.g. IT management, payment processing, data analysis, customer support, cloud storage, fulfilment and shipping).

  • We share personal data with business and marketing partners who provide marketing services to you and display advertisements to you. For example, we use Shopify to support personalised advertising through third-party services based on your online activity across various retailers and websites. Our business and marketing partners use your data in accordance with their own privacy policies. Depending on where you live, you may have the right to instruct us not to share information about you for the purpose of showing you targeted advertising and marketing based on your online activity across various retailers and websites.

  • If you ask us to, or otherwise give your consent to, share certain information with third parties – for example, to deliver products to you – or if you use social media widgets or login integrations.

  • We share personal data with our affiliates or within our group of companies.

  • In connection with a business transaction such as a merger or insolvency; to comply with applicable legal obligations (including responding to subpoenas, search warrants and similar requests); to enforce applicable terms of service or policies; and to protect or defend the Services, our rights, and the rights of our users or others.

 

Relationship with Shopify

The Services are hosted by Shopify, which collects and processes personal data relating to your access to and use of the Services in order to provide and improve the Services for you. Data that you submit to the Services is shared with Shopify and with third parties, who may be located in countries other than your country of residence, in order to provide and improve the Services for you. To protect, expand and improve our business, we also use certain advanced Shopify features that incorporate data and information from your interactions with our shop, with other merchants and with Shopify. To provide these advanced features, Shopify may use personal data collected through your interactions with our shop, other merchants and Shopify. In these circumstances, Shopify is responsible for the processing of your personal data, including responding to your requests to exercise your rights regarding the use of your personal data for these purposes. For more information on how Shopify uses your personal data and what rights you have, please see the Shopify Consumer Privacy Policy. Depending on where you live, you can exercise certain rights regarding your personal data listed here via the link to the Shopify Privacy Portal.

 

Third-party websites and links

The Services may provide links to websites or other online platforms operated by third parties. If you follow links to websites that are not affiliated with us or are not controlled by us, you should review their privacy and security policies, as well as any other terms and conditions. We make no warranties and accept no responsibility for the privacy or security of such websites, including the accuracy, completeness or reliability of the information contained on those websites. Information that you provide in public or semi-public areas, including information you share on third-party social networking platforms, may also be viewed by other users of the Services and/or users of these third-party platforms, without any restrictions on its use by us or by a third party. The inclusion of such links by us does not imply that we endorse the content of these platforms or their owners or operators, unless this is expressly stated in the Services.

 

Children’s Data

The Services are not intended for use by children, and we do not knowingly collect personal data from children who are under the legal age of majority in your country. If you are the parent or guardian of a child who has provided us with their personal data, you may contact us using the contact details provided below to request the deletion of that data. As of the effective date of this Privacy Policy, we are not aware that we “share” or “sell” (as those terms are defined under applicable law) personal data of individuals under the age of 16.

 

Security and retention of your data

Please note that no security measures are perfect or impenetrable, and we therefore cannot guarantee ‘perfect security’. Furthermore, information you send to us may be exposed to risks during transmission. We recommend that you do not use unsecure channels when sending sensitive or confidential information to us.

How long we retain your personal data depends on various factors. These include, for example, whether we need the data to manage your account, provide services to you, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies.

 

Your rights and options

Depending on where you live, you may have some or all of the rights listed below in relation to your personal data. However, these rights are not absolute; they may only apply in certain circumstances, and in some cases we may refuse your request to the extent permitted by law.

  • Right of access/information. You may have the right to request access to the personal data we hold about you.

     

  • Right to erasure. You may have the right to request that we erase the personal data we hold about you.

     

  • Right to rectification. You may have the right to request that we rectify any inaccurate personal data we hold about you.

     

  • Right to data portability. You may have the right to receive a copy of the personal data we hold about you and to request that we transfer it to a third party, subject to certain conditions and exceptions.

     

  • Managing communication settings. We may send you promotional emails. You may opt out of receiving these emails at any time by using the unsubscribe option included in our emails to you. If you opt out, we may still send you non-promotional emails, e.g. regarding your account or orders you have placed.

If you are resident in the United Kingdom or the European Economic Area, subject to any exceptions and restrictions under local law, you may exercise the following rights in addition to those set out above:

  • Right to object and right to restrict processing. You may have the right to request that we cease or restrict the processing of personal data for specific purposes.

  • Withdrawal of consent. Where we rely on your consent to process your personal data, you have the right to withdraw that consent. If you withdraw your consent, this will not affect the lawfulness of the processing based on your consent prior to withdrawal.

You can exercise these rights where indicated within the Services, or by contacting us using the contact details provided below. For more information on how Shopify uses your personal data and what rights you have, including rights relating to the data processed by Shopify, please visit https://privacy.shopify.com/en.

Exercising these rights will not result in any disadvantage to you. Where permitted or required by applicable law, we may need to verify your identity before we can process your requests. In accordance with applicable laws, you may appoint an authorised representative to make requests on your behalf to exercise your rights. Before we accept such a request from a representative, we will require them to provide proof that you have authorised them to act on your behalf. This may require you to confirm your identity directly to us. We will respond to your request promptly in accordance with applicable law.

 

Complaints

If you have any complaints about how we process your personal data, please contact us using the contact details provided below. Depending on where you are resident, you have the right to object to our decision by contacting us using the contact details provided below or by submitting your complaint to the relevant data protection authority. For the European Economic Area, there is a list of competent data protection supervisory authorities. If you wish to view this list, you can do so here.


International transfers

Please note that we may transfer, store and process your personal data outside the country in which you reside.

Where we transfer your personal data outside the European Economic Area or the United Kingdom, we rely on recognised transfer mechanisms such as the European Commission’s Standard Contractual Clauses or equivalent contracts issued by the relevant UK authority, unless the data transfer is to a country that has been demonstrated to offer an adequate level of protection.

 

Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect changes to our practices, or for other operational, legal or regulatory reasons. We will publish the revised Privacy Policy on this website, update the ‘Last Updated’ date accordingly, and provide the notification required by applicable law.

 

Contact

If you have any questions about our data protection procedures or this privacy policy, or if you wish to exercise any of your rights, please contact us by telephone on , or by email at elfriedekastulus@gmail.com. In accordance with applicable data protection laws, we are the data controller for your personal data.